login failed for scitation.aip.org in IDP3

Cantor, Scott cantor.2 at osu.edu
Sun Mar 13 12:45:59 EDT 2016


On 3/13/16, 11:57 AM, "users on behalf of Tom Scavo" <users-bounces at shibboleth.net on behalf of trscavo at gmail.com> wrote:


>
>You have a single signing certificate in metadata that serves two
>functions, that is, a SAML message signing certificate and a
>back-channel TLS certificate. I believe IdP V3 is configured for
>separate, distinct certificates out-of-the-box,

If you ignore the documentation and don't upgrade, yes.

> so you need to figure
>out how to configure V3 to use the same certificate for both purposes
>(to match your metadata).

The IdP is not a web server, it's the web server that has a certificate configured for a second port. Even if the IdP generated one, it's the deployer that makes the decision which one to use.

-- Scott

>


More information about the users mailing list